Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
BID:10933
Info
Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 10933 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2004 12:00AM |
| Updated: | Aug 12 2004 12:00AM |
| Credit: | Ziv Kamir disclosed these vulnerabilities. |
| Vulnerable: |
Keene Digital Media Server 1.0.2 |
| Not Vulnerable: | |
Discussion
Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
It is reported that DMS is susceptible to a directory traversal vulnerability, and an administrative access authentication bypass vulnerability.
The directory traversal issue is due to insufficient sanitization of user-supplied data. An attacker may exploit this vulnerability in order to disclose web server readable files that exist outside of the web root on the vulnerable server.
The administrative access authentication bypass vulnerability is present when an attacker directly accesses the URI of the administrative script.
These vulnerabilities allow a remote attacker to administer the application, or retrieve potentially sensitive files, possibly aiding them in further system compromise.
Version 1.0.2 of the software is reported vulnerable to these issues. Other versions may also be affected.
It is reported that DMS is susceptible to a directory traversal vulnerability, and an administrative access authentication bypass vulnerability.
The directory traversal issue is due to insufficient sanitization of user-supplied data. An attacker may exploit this vulnerability in order to disclose web server readable files that exist outside of the web root on the vulnerable server.
The administrative access authentication bypass vulnerability is present when an attacker directly accesses the URI of the administrative script.
These vulnerabilities allow a remote attacker to administer the application, or retrieve potentially sensitive files, possibly aiding them in further system compromise.
Version 1.0.2 of the software is reported vulnerable to these issues. Other versions may also be affected.
Exploit / POC
Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities
References:
References: